Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
CVE-2023-44374
6.5 (3.1)
7.1 (4.0)
A vulnerability has been identified in RUGGEDCOM … Siemens
RUGGEDCOM RM1224 LTE(4G) EU
2023-11-14T11:04:13.329Z 2026-02-25T16:51:09.847Z
CVE-2023-22668
6.7 (3.1)
Use After Free in Audio Qualcomm, Inc.
Snapdragon
2023-12-05T03:03:45.703Z 2026-02-25T16:51:09.659Z
CVE-2023-28546
7.8 (3.1)
Buffer Copy Without Checking Size of Input in SPS Appl… Qualcomm, Inc.
Snapdragon
2023-12-05T03:03:46.993Z 2026-02-25T16:51:09.392Z
CVE-2023-28585
8.2 (3.1)
Integer Overflow to Buffer Overflow in TZ Secure OS Qualcomm, Inc.
Snapdragon
2023-12-05T03:03:53.662Z 2026-02-25T16:51:08.675Z
CVE-2023-33024
6.7 (3.1)
Buffer Copy Without Checking Size of Input (`Classic B… Qualcomm, Inc.
Snapdragon
2023-12-05T03:04:03.310Z 2026-02-25T16:51:08.468Z
CVE-2023-33071
8.4 (3.1)
Improper Access Control in Automotive OS Platform Android Qualcomm, Inc.
Snapdragon
2023-12-05T03:04:13.352Z 2026-02-25T16:51:08.257Z
CVE-2023-33082
9.8 (3.1)
Buffer Copy Without Checking Size of Input (`Classic B… Qualcomm, Inc.
Snapdragon
2023-12-05T03:04:18.133Z 2026-02-25T16:51:07.770Z
CVE-2026-2479
5 (3.1)
Responsive Lightbox & Gallery <= 2.7.1 - Authenticated… dfactory
Responsive Lightbox & Gallery
2026-02-25T08:25:30.385Z 2026-02-25T16:51:05.012Z
CVE-2023-6333
7.5 (3.1)
Cross-site Scripting in ControlByWeb Relays ControlByWeb
X-332-24I
2023-12-07T18:08:04.324Z 2026-02-25T16:50:54.327Z
CVE-2026-1916
7.5 (3.1)
WPGSI: Spreadsheet Integration <= 3.8.3 - Missing Auth… javmah
WPGSI: Spreadsheet Integration
2026-02-25T08:25:31.051Z 2026-02-25T16:50:00.569Z
CVE-2020-14381
7.8 (3.1)
A flaw was found in the Linux kernel’s futex impl… n/a
kernel
2020-12-03T16:21:55.000Z 2026-02-25T16:48:37.567Z
CVE-2024-50452
6.5 (3.1)
WordPress Nexter Blocks plugin <= 3.3.3 - Cross Site S… POSIMYTH
Nexter Blocks
2026-02-20T15:46:25.053Z 2026-02-25T16:48:11.776Z
CVE-2026-27739
9.2 (4.0)
Angular SSR is vulnerable to SSRF and Header Injection… angular
angular-cli
2026-02-25T16:47:29.705Z 2026-02-25T16:47:29.705Z
CVE-2026-1144
5.3 (4.0)
6.3 (3.1)
6.3 (3.0)
quickjs-ng quickjs Atomics Ops quickjs.c use after free quickjs-ng
quickjs
2026-01-19T07:32:10.363Z 2026-02-25T16:46:28.328Z
CVE-2026-1145
5.3 (4.0)
6.3 (3.1)
6.3 (3.0)
quickjs-ng quickjs quickjs.c js_typed_array_constructo… quickjs-ng
quickjs
2026-01-19T08:02:08.519Z 2026-02-25T16:45:03.206Z
CVE-2024-51915
6.5 (3.1)
WordPress LiteSpeed Cache plugin <= 6.5.2 - Cross Site… LiteSpeed Technologies
LiteSpeed Cache
2026-02-20T15:46:25.475Z 2026-02-25T16:44:09.359Z
CVE-2026-21528
6.5 (3.1)
Azure IoT Explorer Information Disclosure Vulnerability Microsoft
Azure IoT Explorer
2026-02-10T17:51:30.773Z 2026-02-25T16:43:35.894Z
CVE-2025-69873
2.9 (3.1)
ajv (Another JSON Schema Validator) before 8.18.0… ajv.js
ajv
2026-02-11T00:00:00.000Z 2026-02-25T16:42:35.482Z
CVE-2026-23491
9.3 (4.0)
InvoicePlane has Unauthenticated Path Traversal in Gue… InvoicePlane
InvoicePlane
2026-02-18T19:52:26.304Z 2026-02-25T16:41:34.879Z
CVE-2023-5427
7.8 (3.1)
Mali GPU Kernel Driver allows improper GPU processing … Arm Ltd
Bifrost GPU Kernel Driver
2023-12-01T10:13:49.299Z 2026-02-25T16:41:07.193Z
CVE-2026-27738
6.9 (4.0)
Angular SSR has an Open Redirect via X-Forwarded-Prefix angular
angular-cli
2026-02-25T16:40:44.724Z 2026-02-25T16:40:44.724Z
CVE-2024-54222
4.3 (3.1)
WordPress Seraphinite Accelerator plugin <= 2.22.15 - … Seraphinite Solutions
Seraphinite Accelerator
2026-02-20T15:46:25.825Z 2026-02-25T16:39:20.709Z
CVE-2026-2416
7.5 (3.1)
Geo Mashup <= 1.13.17 - Unauthenticated SQL Injection … cyberhobo
Geo Mashup
2026-02-25T08:25:31.427Z 2026-02-25T16:37:56.454Z
CVE-2026-1929
8.8 (3.1)
Advanced Woo Labels <= 2.37 - Authenticated (Contribut… mihail-barinov
Advanced Woo Labels – Product Labels & Badges for WooCommerce
2026-02-25T08:25:31.823Z 2026-02-25T16:37:12.800Z
CVE-2026-3171
5.1 (4.0)
3.5 (3.1)
3.5 (3.0)
SourceCodester/Patrick Mvuma Patients Waiting Area Que… SourceCodester
Patients Waiting Area Queue Management System
2026-02-25T08:32:07.369Z 2026-02-25T16:34:51.471Z
CVE-2023-49583
9.1 (3.1)
Escalation of Privileges in SAP BTP Security Services … SAP_SE
@sap/xssec
2023-12-12T01:22:58.910Z 2026-02-25T16:34:36.422Z
CVE-2023-50422
9.1 (3.1)
Escalation of Privileges in SAP BTP Security Services … SAP_SE
cloud-security-services-integration-library
2023-12-12T01:31:17.991Z 2026-02-25T16:34:36.244Z
CVE-2023-50423
9.1 (3.1)
Escalation of Privileges in SAP BTP Security Services … SAP_SE
sap-xssec
2023-12-12T01:52:44.999Z 2026-02-25T16:34:36.085Z
CVE-2023-50424
9.1 (3.1)
Escalation of Privileges in SAP BTP Security Services … SAP_SE
github.com/sap/cloud-security-client-go
2023-12-12T01:59:36.703Z 2026-02-25T16:34:35.943Z
CVE-2022-47374
7.5 (3.1)
A vulnerability has been identified in SIMATIC PC… Siemens
SIMATIC PC-Station Plus
2023-12-12T11:25:31.314Z 2026-02-25T16:34:35.793Z
ID CVSS Description Vendor Product Published Updated
ID Description Published Updated
fkie_cve-2023-26302 Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, i… 2023-02-22T23:15:17.677 2026-02-25T17:19:19.280
fkie_cve-2023-24489 A vulnerability has been discovered in the customer-managed ShareFile storage zones controller whic… 2023-07-10T22:15:09.197 2026-02-25T17:19:01.213
fkie_cve-2023-23841 SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File S… 2023-06-15T22:15:09.227 2026-02-25T17:18:56.540
fkie_cve-2026-21912 A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethe… 2026-01-15T21:16:07.357 2026-02-25T17:18:19.927
fkie_cve-2026-1849 MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce de… 2026-02-10T19:15:51.477 2026-02-25T17:17:56.350
fkie_cve-2026-21910 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engi… 2026-01-15T21:16:06.920 2026-02-25T17:17:44.337
fkie_cve-2026-28196 In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk 2026-02-25T14:16:21.200 2026-02-25T17:17:14.643
fkie_cve-2023-0919 Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0. 2023-02-19T15:15:10.433 2026-02-25T17:17:14.347
fkie_cve-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function … 2023-03-01T08:15:11.530 2026-02-25T17:17:09.550
fkie_cve-2023-0342 MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings… 2023-06-09T09:15:09.383 2026-02-25T17:17:07.243
fkie_cve-2026-28195 In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add para… 2026-02-25T14:16:21.040 2026-02-25T17:17:05.450
fkie_cve-2023-0026 An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks… 2023-06-21T17:15:47.597 2026-02-25T17:17:02.917
fkie_cve-2026-28194 In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow 2026-02-25T14:16:20.880 2026-02-25T17:16:54.070
fkie_cve-2026-27586 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swall… 2026-02-24T17:29:03.793 2026-02-25T17:14:19.867
fkie_cve-2026-27518 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protectio… 2026-02-24T16:24:09.407 2026-02-25T17:13:33.390
fkie_cve-2026-27517 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized… 2026-02-24T16:24:09.207 2026-02-25T17:13:20.987
fkie_cve-2026-27585 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path … 2026-02-24T17:29:03.620 2026-02-25T17:13:16.240
fkie_cve-2026-27516 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwor… 2026-02-24T16:24:09.030 2026-02-25T17:12:32.883
fkie_cve-2026-23678 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command i… 2026-02-24T16:24:08.090 2026-02-25T17:12:08.403
fkie_cve-2026-27587 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's H… 2026-02-24T17:29:03.953 2026-02-25T17:11:25.233
fkie_cve-2026-1850 Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Me… 2026-02-10T19:15:51.633 2026-02-25T17:11:10.953
fkie_cve-2026-27588 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's H… 2026-02-24T17:29:04.163 2026-02-25T17:10:48.980
fkie_cve-2026-27589 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local… 2026-02-24T17:29:04.317 2026-02-25T17:08:56.040
fkie_cve-2026-27590 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's F… 2026-02-24T17:29:04.493 2026-02-25T17:07:09.600
fkie_cve-2026-27507 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded … 2026-02-24T16:24:08.617 2026-02-25T17:05:34.330
fkie_cve-2025-67491 OpenEMR is a free and open source electronic health records and medical practice management applica… 2026-02-25T01:16:08.963 2026-02-25T17:01:48.460
fkie_cve-2025-69231 OpenEMR is a free and open source electronic health records and medical practice management applica… 2026-02-25T02:16:21.707 2026-02-25T17:01:10.910
fkie_cve-2025-68277 OpenEMR is a free and open source electronic health records and medical practice management applica… 2026-02-25T02:16:21.537 2026-02-25T17:00:23.377
fkie_cve-2025-67752 OpenEMR is a free and open source electronic health records and medical practice management applica… 2026-02-25T02:16:21.377 2026-02-25T16:58:43.827
fkie_cve-2026-24849 OpenEMR is a free and open source electronic health records and medical practice management applica… 2026-02-25T02:16:22.197 2026-02-25T16:56:53.200
ID Severity Description Published Updated
ghsa-3pw3-vpq3-qmc9
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:37Z 2026-02-24T21:31:38Z
ghsa-rrpc-76pm-5w54
7.5 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-rmj8-x3h3-24rh
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-q577-6r28-hw22
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-p69v-gqh4-hg9p
9.8 (3.1)
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injectio… 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-mhqr-8rx2-jw82
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-4wc7-crf4-r645
8.8 (3.1)
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager bookin… 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-48pc-4fq3-jhwg
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-2wf2-988r-jv99
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-2rf2-f6mm-2232
5.3 (3.1)
Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-my… 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-2cv8-fr2g-g66g
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:36Z
ghsa-vhgp-3x24-vh98
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:35Z 2026-02-24T21:31:35Z
ghsa-r5c8-59gv-v4x8
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-pxxq-rvgm-p9rp
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-p95v-rww3-j83p
7.2 (3.1)
Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Requ… 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-gxg3-7vjc-h392
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-536p-mw62-6cm4
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-37wf-f6wc-vqj8
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-256m-r39j-gmcw
9.3 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:36Z 2026-02-24T21:31:35Z
ghsa-wv4q-94jw-h996
8.8 (3.1)
Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows… 2026-02-20T18:31:35Z 2026-02-24T21:31:34Z
ghsa-wfqx-gw86-rc8h
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:35Z 2026-02-24T21:31:34Z
ghsa-rr5c-93pp-mqfv
9.8 (3.1)
Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection… 2026-02-20T18:31:34Z 2026-02-24T21:31:34Z
ghsa-q6xg-x4rx-4p97
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:35Z 2026-02-24T21:31:34Z
ghsa-jjpv-2mhh-mcmm
9.8 (3.1)
Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Inje… 2026-02-20T18:31:34Z 2026-02-24T21:31:34Z
ghsa-f3xp-j3c9-999x
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:34Z 2026-02-24T21:31:34Z
ghsa-97hf-p3f7-pjq2
8.5 (3.1)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability … 2026-02-20T18:31:34Z 2026-02-24T21:31:34Z
ghsa-7gx4-4vpm-w576
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:34Z 2026-02-24T21:31:34Z
ghsa-4ff7-6hm2-x86r
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:35Z 2026-02-24T21:31:34Z
ghsa-3h5g-fffj-jhx9
7.5 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:35Z 2026-02-24T21:31:34Z
ghsa-mwrf-hg69-6h5g
8.1 (3.1)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusi… 2026-02-20T18:31:34Z 2026-02-24T21:31:33Z
ID Severity Description Package Published Updated
pysec-2017-138
5.5 (3.1)
There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.398419Z
pysec-2017-137
5.5 (3.1)
An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in E… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.340172Z
pysec-2017-136
5.5 (3.1)
A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.277896Z
pysec-2017-135
5.5 (3.1)
An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.c… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.218172Z
pysec-2017-134
5.5 (3.1)
There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function … exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.157939Z
pysec-2017-133
5.5 (3.1)
There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of j… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.10072Z
pysec-2017-132
5.5 (3.1)
An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in v… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:47.041853Z
pysec-2017-131
5.5 (3.1)
There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:46.982152Z
pysec-2017-130
5.5 (3.1)
In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a S… exiv2 2017-09-29T01:34:00Z 2024-11-21T14:22:46.923551Z
pysec-2017-129
6.5 (3.1)
There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the… exiv2 2017-08-18T21:29:00Z 2024-11-21T14:22:46.862068Z
pysec-2017-128
6.5 (3.1)
There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of … exiv2 2017-08-18T21:29:00Z 2024-11-21T14:22:46.791764Z
pysec-2017-127
8.8 (3.1)
There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26. The vulnerability cau… exiv2 2017-08-18T21:29:00Z 2024-11-21T14:22:46.732582Z
pysec-2017-126
6.5 (3.1)
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in ti… exiv2 2017-07-27T06:29:00Z 2024-11-21T14:22:46.672784Z
pysec-2017-125
7.5 (3.1)
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek… exiv2 2017-07-24T01:29:00Z 2024-11-21T14:22:46.598979Z
pysec-2017-124
7.5 (3.1)
There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that w… exiv2 2017-07-24T01:29:00Z 2024-11-21T14:22:46.539614Z
pysec-2017-123
7.5 (3.1)
There is an illegal address access in the extend_alias_table function in localealias.c of… exiv2 2017-07-23T03:29:00Z 2024-11-21T14:22:46.480449Z
pysec-2017-122
6.5 (3.1)
There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, relat… exiv2 2017-07-17T13:18:00Z 2024-11-21T14:22:46.411851Z
pysec-2017-121
6.5 (3.1)
There is a heap-based buffer overflow in the Image::printIFDStructure function of image.c… exiv2 2017-07-17T13:18:00Z 2024-11-21T14:22:46.352202Z
pysec-2017-120
6.5 (3.1)
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in… exiv2 2017-07-17T13:18:00Z 2024-11-21T14:22:46.291386Z
pysec-2017-119
6.5 (3.1)
There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in E… exiv2 2017-07-17T13:18:00Z 2024-11-21T14:22:46.232444Z
pysec-2017-118
6.5 (3.1)
There is a heap-based buffer over-read in the Image::printIFDStructure function in image.… exiv2 2017-07-17T13:18:00Z 2024-11-21T14:22:46.174866Z
pysec-2017-117
5.5 (3.1)
Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser exiv2 2017-11-17T22:29:00Z 2024-11-21T14:22:46.115176Z
pysec-2017-116
5.5 (3.1)
Exiv2 0.26 contains a heap buffer overflow in tiff parser exiv2 2017-11-17T22:29:00Z 2024-11-21T14:22:46.052386Z
pysec-2017-115
5.5 (3.1)
exiv2 0.26 contains a Stack out of bounds read in webp parser exiv2 2017-11-17T22:29:00Z 2024-11-21T14:22:45.992477Z
pysec-2015-36
Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24… exiv2 2015-01-02T20:59:00Z 2024-11-21T14:22:45.931449Z
pysec-2008-11
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-… exiv2 2008-06-13T19:41:00Z 2024-11-21T14:22:45.866207Z
pysec-2021-881
7.5 (3.1)
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIB… eftl 2021-10-05T18:15:00Z 2024-11-21T14:22:45.803448Z
pysec-2022-43133
9.8 (3.1)
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor v… drxhello 2022-06-24T21:15:00Z 2024-11-21T14:22:45.663614Z
pysec-2022-43132
9.8 (3.1)
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution bac… dr-web-engine 2022-06-24T21:15:00Z 2024-11-21T14:22:45.610409Z
pysec-2024-125
7.5 (3.1)
DIRAC is a distributed resource framework. In affected versions any user could get a toke… dirac 2024-02-09T00:15:00+00:00 2024-11-21T14:22:45.495938+00:00
ID Description Type
ID Description Updated
gsd-2024-27202 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:15.043072Z
gsd-2024-26026 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:14.001780Z
gsd-2024-28889 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:12.636165Z
gsd-2024-28880 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:12.392410Z
gsd-2024-28883 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:12.389367Z
gsd-2024-28132 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:12.156611Z
gsd-2024-25560 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.926102Z
gsd-2024-33564 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.690855Z
gsd-2024-33599 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.689695Z
gsd-2024-33569 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.689024Z
gsd-2024-33542 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.688591Z
gsd-2024-33592 Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affec… 2024-04-25T05:02:10.687617Z
gsd-2024-33608 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.687145Z
gsd-2024-33580 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.684958Z
gsd-2024-33527 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.684742Z
gsd-2024-33532 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.683477Z
gsd-2024-33531 cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks… 2024-04-25T05:02:10.682199Z
gsd-2024-33582 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.681866Z
gsd-2024-33578 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.679697Z
gsd-2024-33588 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.676199Z
gsd-2024-33585 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.675953Z
gsd-2024-33597 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.675513Z
gsd-2024-33593 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.673021Z
gsd-2024-33539 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.670372Z
gsd-2024-33579 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.669859Z
gsd-2024-33584 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.668914Z
gsd-2024-33549 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.667701Z
gsd-2024-33554 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.667501Z
gsd-2024-33552 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.667300Z
gsd-2024-33536 The format of the source doesn't require a description, click on the link for more details. 2024-04-25T05:02:10.665589Z
ID Description Published Updated
mal-2026-686 Malicious code in tableapys (PyPI) 2026-02-03T07:49:06Z 2026-02-03T09:19:13Z
mal-2026-697 Malicious code in pathlib-v2-utility (PyPI) 2026-02-03T09:17:38Z 2026-02-03T09:17:38Z
mal-2026-638 Malicious code in solhint-plugin-hyperlane (npm) 2026-02-02T05:19:43Z 2026-02-03T08:27:44Z
mal-2026-634 Malicious code in eslint-config-minecraft-scripting (npm) 2026-02-02T05:19:43Z 2026-02-03T08:27:41Z
mal-2026-594 Malicious code in epic-asset-uploader (npm) 2026-01-28T19:45:45Z 2026-02-03T08:27:41Z
mal-2026-554 Malicious code in braintree-web-latest (npm) 2026-01-25T19:34:34Z 2026-02-03T04:54:38Z
mal-2026-496 Malicious code in hemi-btc-staking-actions (npm) 2026-01-23T18:12:42Z 2026-02-03T04:04:59Z
mal-2026-617 Malicious code in roots-cms-client (npm) 2026-01-31T17:27:21Z 2026-02-03T03:16:53Z
mal-2025-49435 Malicious code in something-not-in-cache (npm) 2025-11-09T00:17:09Z 2026-02-03T03:16:53Z
mal-2026-637 Malicious code in launchdarkly-cpp-networking (npm) 2026-02-02T05:19:43Z 2026-02-03T03:16:52Z
mal-2024-2834 Malicious code in pap-client (npm) 2024-06-25T12:55:07Z 2026-02-03T03:16:52Z
mal-2026-655 Malicious code in pipeline-poision-test (PyPI) 2026-02-02T21:53:29Z 2026-02-02T21:53:29Z
mal-2026-648 Malicious code in yazxzpedia (npm) 2026-02-02T08:27:24Z 2026-02-02T18:50:28Z
mal-2026-647 Malicious code in react-native-expofp (npm) 2026-02-02T08:30:15Z 2026-02-02T18:50:26Z
mal-2026-646 Malicious code in picking-miniapp (npm) 2026-02-02T08:30:53Z 2026-02-02T18:50:26Z
mal-2026-645 Malicious code in libsignal-yazxzpedia (npm) 2026-02-02T08:27:24Z 2026-02-02T18:50:25Z
mal-2026-644 Malicious code in dise-pkt (npm) 2026-02-02T08:29:38Z 2026-02-02T18:50:24Z
mal-2026-643 Malicious code in @hemanshu_patil/xcode-windows-x64 (npm) 2026-02-02T08:28:43Z 2026-02-02T18:50:22Z
mal-2026-642 Malicious code in @hemanshu_patil/xcode (npm) 2026-02-02T08:28:43Z 2026-02-02T18:50:22Z
mal-2026-651 Malicious code in cat-admin-tool (PyPI) 2026-02-02T14:44:25Z 2026-02-02T14:44:25Z
mal-2026-652 Malicious code in chia-pool-reference (PyPI) 2026-02-02T14:43:22Z 2026-02-02T14:43:22Z
mal-2026-653 Malicious code in credit-decision-metrics (PyPI) 2026-02-02T14:42:50Z 2026-02-02T14:42:50Z
mal-2026-654 Malicious code in zabitog (PyPI) 2026-02-02T14:41:04Z 2026-02-02T14:41:04Z
mal-2026-650 Malicious code in tableapy (PyPI) 2026-02-02T12:56:55Z 2026-02-02T12:56:55Z
mal-2026-649 Malicious code in callapirequests (PyPI) 2026-02-02T09:08:10Z 2026-02-02T09:08:10Z
mal-2026-641 Malicious code in connections-api-requests (PyPI) 2026-02-02T06:54:40Z 2026-02-02T06:54:40Z
mal-2026-640 Malicious code in connections-api-request (PyPI) 2026-02-02T06:52:24Z 2026-02-02T06:52:24Z
mal-2026-639 Malicious code in connection-api-requests (PyPI) 2026-02-02T06:49:31Z 2026-02-02T06:49:31Z
mal-2026-616 Malicious code in c11dff444 (npm) 2026-01-31T16:58:54Z 2026-02-02T06:41:02Z
mal-2026-598 Malicious code in wallet-icon-font (npm) 2026-01-29T03:47:06Z 2026-02-02T05:56:31Z
ID Description Published Updated
bit-zookeeper-2025-58457 Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands 2025-09-26T08:51:26.070Z 2025-11-06T13:25:46.476Z
bit-wildfly-2021-3644 2024-03-06T11:08:38.390Z 2025-11-06T13:25:46.476Z
bit-vault-2024-6468 Vault Vulnerable to Denial of Service When Setting a Proxy Protocol Behavior 2024-07-17T07:39:35.824Z 2025-11-06T13:25:46.476Z
bit-valkey-2025-49844 Redis Lua Use-After-Free may lead to remote code execution 2025-10-16T09:19:55.260Z 2025-11-06T13:25:46.476Z
bit-valkey-2025-48367 Redis DoS Vulnerability due to bad connection error handling 2025-10-16T12:08:13.783Z 2025-11-06T13:25:46.476Z
bit-valkey-2025-46819 Redis is vulnerable to DoS via specially crafted LUA scripts 2025-10-08T08:52:39.220Z 2025-11-06T13:25:46.476Z
bit-valkey-2025-46818 Redis: Authenticated users can execute LUA scripts as a different user 2025-10-08T08:52:37.720Z 2025-11-06T13:25:46.476Z
bit-valkey-2025-27151 redis-check-aof may lead to stack overflow and potential RCE 2025-05-31T06:02:22.962Z 2025-11-06T13:25:46.476Z
bit-valkey-2024-31449 Lua library commands may lead to stack overflow and RCE in Redis 2024-10-09T16:44:28.833Z 2025-11-06T13:25:46.476Z
bit-valkey-2024-31228 Denial-of-service due to unbounded pattern matching in Redis 2024-10-09T16:44:40.936Z 2025-11-06T13:25:46.476Z
bit-valkey-2024-31227 Denial-of-service due to malformed ACL selectors in Redis 2024-10-09T16:44:53.016Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-61795 Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS 2025-11-06T13:00:35.478Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-55754 Apache Tomcat: console manipulation via escape sequences in log messages 2025-11-06T13:00:33.572Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-55668 Apache Tomcat: session fixation via rewrite valve 2025-08-18T08:14:21.163Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-53506 Apache Tomcat: DoS via excessive h2 streams at connection start 2025-07-16T08:19:04.361Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-52520 Apache Tomcat: DoS via integer overflow in multipart file upload 2025-07-16T08:19:00.271Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-52434 Apache Tomcat: APR/Native Connector crash leading to DoS 2025-07-16T08:18:56.172Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-49125 Apache Tomcat: Security constraint bypass for pre/post-resources 2025-07-10T10:47:18.953Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-49124 Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows 2025-06-20T06:04:24.795Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-48989 Apache Tomcat: h2 DoS - Made You Reset 2025-08-18T08:14:11.138Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-48988 Apache Tomcat: FileUpload large number of parts with headers DoS 2025-07-10T10:47:06.961Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-46701 Apache Tomcat: Security constraint bypass for CGI scripts 2025-07-10T10:47:00.568Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-31651 Apache Tomcat: Bypass of rules in Rewrite Valve 2025-07-10T10:46:54.240Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-31650 Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame 2025-04-30T05:56:04.703Z 2025-11-06T13:25:46.476Z
bit-tomcat-2025-24813 Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT 2025-07-10T10:46:47.051Z 2025-11-06T13:25:46.476Z
bit-tomcat-2024-56337 Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete 2025-07-10T10:46:39.151Z 2025-11-06T13:25:46.476Z
bit-tomcat-2024-54677 Apache Tomcat: DoS in examples web application 2025-07-10T10:46:30.955Z 2025-11-06T13:25:46.476Z
bit-tomcat-2024-52317 Apache Tomcat: Request/response mix-up with HTTP/2 2024-11-20T07:20:06.896Z 2025-11-06T13:25:46.476Z
bit-tomcat-2024-52316 Apache Tomcat: Authentication bypass when using Jakarta Authentication API 2025-07-10T10:46:05.150Z 2025-11-06T13:25:46.476Z
bit-tomcat-2024-50379 Apache Tomcat: RCE due to TOCTOU issue in JSP compilation 2025-07-10T10:45:55.643Z 2025-11-06T13:25:46.476Z
ID Description Updated
ID Description Published Updated
jvndb-2023-000011 SUSHIRO App for Android outputs sensitive information to the log file 2023-01-31T14:10+09:00 2024-06-11T17:35+09:00
jvndb-2023-001269 File and Directory Permissions Vulnerability in Hitachi Automation Director, Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center 2023-03-01T16:59+09:00 2024-06-11T16:42+09:00
jvndb-2023-000014 NEC PC Settings Tool vulnerable to missing authentication for critical function 2023-02-10T14:43+09:00 2024-06-10T18:13+09:00
jvndb-2023-000019 Multiple cross-site scripting vulnerabilities in EC-CUBE 2023-02-28T16:38+09:00 2024-06-10T17:28+09:00
jvndb-2023-001212 Multiple vulnerabilities in JTEKT ELECTRONICS Screen Creator Advance 2 2023-02-08T12:46+09:00 2024-06-10T17:25+09:00
jvndb-2023-000018 Multiple cross-site scripting vulnerabilities in SHIRASAGI 2023-02-22T15:16+09:00 2024-06-10T17:18+09:00
jvndb-2024-000058 WordPress Plugin "Music Store - WordPress eCommerce" vulnerable to SQL injection 2024-06-07T15:24+09:00 2024-06-10T17:08+09:00
jvndb-2023-000023 Multiple vulnerabilities in PostgreSQL extension module pg_ivm 2023-03-06T15:22+09:00 2024-06-10T16:41+09:00
jvndb-2023-001292 Multiple vulnerabilities in Trend Micro Apex One and Apex One as a Service 2023-03-02T17:33+09:00 2024-06-07T16:59+09:00
jvndb-2023-001304 Multiple vulnerabilities in JTEKT ELECTRONICS Kostac PLC Programming Software 2023-03-06T15:31+09:00 2024-06-07T16:39+09:00
jvndb-2023-000020 web2py development tool vulnerable to open redirect 2023-02-28T15:00+09:00 2024-06-07T16:31+09:00
jvndb-2024-000060 Multiple vulnerabilities in "FreeFrom - the nostr client" App 2024-06-07T14:51+09:00 2024-06-07T14:51+09:00
jvndb-2023-000021 Multiple vulnerabilities in SS1 and Rakuraku PC Cloud 2023-03-01T15:57+09:00 2024-06-06T18:02+09:00
jvndb-2022-000086 Aiphone Video Multi-Tenant System Entrance Stations vulnerable to information disclosure 2022-11-10T13:40+09:00 2024-06-06T17:37+09:00
jvndb-2023-000028 baserCMS vulnerable to arbitrary file uploads 2023-03-27T13:39+09:00 2024-06-06T17:31+09:00
jvndb-2022-000079 Multiple vulnerabilities in the web interfaces of Kyocera Document Solutions MFPs and printers 2022-11-01T14:51+09:00 2024-06-06T17:01+09:00
jvndb-2022-000084 Multiple vulnerabilities in FUJI SOFT network devices 2022-10-28T15:12+09:00 2024-06-06T16:48+09:00
jvndb-2022-000087 Multiple vulnerabilities in WordPress 2022-11-08T14:59+09:00 2024-06-06T16:27+09:00
jvndb-2022-000088 TERASOLUNA Global Framework and TERASOLUNA Server Framework for Java (Rich) vulnerable to ClassLoader manipulation 2022-11-14T16:45+09:00 2024-06-06T16:11+09:00
jvndb-2022-000085 WordPress Plugin "Salon booking system" vulnerable to cross-site scripting 2022-11-08T15:07+09:00 2024-06-05T18:07+09:00
jvndb-2022-000082 Multiple vulnerabilities in nadesiko3 2022-10-20T16:58+09:00 2024-06-05T17:28+09:00
jvndb-2023-000010 pgAdmin 4 vulnerable to directory traversal 2023-01-24T16:00+09:00 2024-06-05T16:22+09:00
jvndb-2022-000083 Multiple vulnerabilities in SHIRASAGI 2022-10-25T15:10+09:00 2024-06-05T16:06+09:00
jvndb-2023-001402 JTEKT ELECTRONIC Screen Creator Advance 2 vulnerable to improper restriction of operations within the bounds of a memory buffer 2023-04-03T16:24+09:00 2024-06-04T17:15+09:00
jvndb-2022-002770 Contec SolarView Compact vulnerable to cross-site scripting 2022-12-06T15:08+09:00 2024-06-04T17:13+09:00
jvndb-2023-001320 Multiple vulnerabilities in Contec CONPROSYS IoT Gateway products 2023-03-22T13:41+09:00 2024-06-04T17:00+09:00
jvndb-2023-000025 TP-Link T2600G-28SQ uses vulnerable SSH host keys 2023-03-17T12:27+09:00 2024-06-04T16:58+09:00
jvndb-2023-001308 Multiple vulnerabilities in Buffalo network devices 2023-03-08T15:12+09:00 2024-06-04T16:42+09:00
jvndb-2023-000030 HAProxy vulnerable to HTTP request/response smuggling 2023-03-31T15:54+09:00 2024-06-04T16:17+09:00
jvndb-2023-000032 Improper restriction of XML external entity references (XXE) in National land numerical information data conversion tool 2023-04-04T15:22+09:00 2024-06-04T15:56+09:00
ID Description Updated
ID Description
ID Description Published Updated
cnvd-2026-04432 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2025-923949) 2025-11-25 2026-01-22
cnvd-2026-04429 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2025-859399) 2025-11-17 2026-01-22
cnvd-2026-04428 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2025-824752) 2025-11-10 2026-01-22
cnvd-2026-04426 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2025-921601) 2025-11-25 2026-01-22
cnvd-2026-04425 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2025-891462) 2025-11-19 2026-01-22
cnvd-2026-04424 北京神州视翰科技有限公司多媒体综合业务显示系统存在SQL注入漏洞(CNVD-C-2025-859401) 2025-11-17 2026-01-22
cnvd-2026-06111 Soda PDF Desktop越界读取漏洞 2026-01-09 2026-01-21
cnvd-2026-06110 Soda PDF Desktop代码执行漏洞(CNVD-2026-06110) 2026-01-09 2026-01-21
cnvd-2026-06108 Soda PDF Desktop代码执行漏洞(CNVD-2026-06108) 2026-01-09 2026-01-21
cnvd-2026-06107 Soda PDF Desktop代码执行漏洞 2026-01-09 2026-01-21
cnvd-2026-06105 Tenda AX1806 SetIPv6Status函数命令注入漏洞 2022-05-07 2026-01-21
cnvd-2026-06103 Tenda AX1806 fromAdvSetMacMtuWan函数堆栈缓冲区溢出漏洞 2022-05-09 2026-01-21
cnvd-2026-06102 Tenda AX1806 sub_455D4函数栈缓冲区溢出漏洞 2023-11-13 2026-01-21
cnvd-2026-06101 Tenda M3 /goform/getMasterPassengerAnalyseData文件堆栈缓冲区溢出漏洞 2025-08-22 2026-01-21
cnvd-2026-06100 Tenda M3 /goform/QuickIndex文件堆栈缓冲区溢出漏洞 2025-08-26 2026-01-21
cnvd-2026-06099 Tenda AX-3 get_parentControl_list_Info函数堆栈缓冲区溢出漏洞 2025-11-05 2026-01-21
cnvd-2026-06098 Tenda M3 /goform/exeCommand文件堆栈缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06097 Tenda M3 /goform/setAdPushInfo文件堆栈缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06096 Tenda M3 /goform/setAdInfoDetail文件堆缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06095 Tenda M3 /goform/setVlanInfo文件堆栈缓冲区溢出漏洞 2026-01-06 2026-01-21
cnvd-2026-06094 Tenda M3 /goform/setInternetLanInfo文件堆缓冲区溢出漏洞 2026-01-14 2026-01-21
cnvd-2026-06093 Tenda AX-3 fromAdvSetMacMtuWan函数栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06092 Tenda AX-3 fromAdvSetMacMtuWan函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06091 Tenda AX-3 fromAdvSetMacMtuWan函数栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06090 Tenda AX-3 fromAdvSetMacMtuWan函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06089 Tenda AX-3 fromAdvSetMacMtuWan函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06088 Tenda AX1806 sub_4CA50函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06087 Tenda AX1806 sub_65B5C函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06086 Tenda AX1806 sub_65B5C函数栈缓冲区溢出漏洞 2026-01-19 2026-01-21
cnvd-2026-06085 Tenda AX1806 sub_65B5C函数堆栈缓冲区溢出漏洞 2026-01-19 2026-01-21
ID Description Published Updated
bdu:2025-12109 Уязвимость ядра операционной системы Linux, связанная с возможностью использования памяти… 28.09.2025 16.02.2026
bdu:2025-12108 Уязвимость ядра операционной системы Linux, связанная с использованием памяти после её ос… 28.09.2025 16.02.2026
bdu:2025-12107 Уязвимость функции find_cifs_entry() в модуле fs/smb/client/readdir.c поддержки клиента S… 28.09.2025 16.02.2026
bdu:2025-12105 Уязвимость ядра операционной системы Linux, связанная с использованием памяти после её ос… 28.09.2025 16.02.2026
bdu:2025-12101 Уязвимость компонента drivers/usb/gadget/udc/core.c ядра операционной системы Linux, позв… 28.09.2025 16.02.2026
bdu:2025-12096 Уязвимость функции ksmbd_sessions_deregister() компонента user_session.c ядра операционно… 28.09.2025 16.02.2026
bdu:2025-12093 Уязвимость функции erdma_accept_newconn() компонента drivers/infiniband/hw/erdma/erdma_cm… 28.09.2025 16.02.2026
bdu:2025-12092 Уязвимость компонента drivers/gpu/drm/vkms ядра операционной системы Linux, позволяющая н… 28.09.2025 16.02.2026
bdu:2025-12091 Уязвимость компонента sctp ядра операционной системы Linux, позволяющая нарушителю вызват… 28.09.2025 16.02.2026
bdu:2025-12089 Уязвимость функции ext4_xattr_inode_dec_ref_all() компонента fs/ext4/xattr.c ядра операци… 28.09.2025 16.02.2026
bdu:2025-12087 Уязвимость компонента sch_hfsc.c ядра операционной системы Linux, позволяющая нарушителю … 28.09.2025 16.02.2026
bdu:2025-12086 Уязвимость компонента irq-gic-v2m.c ядра операционной системы Linux, позволяющая нарушите… 28.09.2025 16.02.2026
bdu:2025-12085 Уязвимость компонента sch_hfsc.c ядра операционной системы Linux, позволяющая нарушителю … 28.09.2025 16.02.2026
bdu:2025-12077 Уязвимость функции rtsx_usb_ms_drv_remove() компонента drivers/memstick/host/rtsx_usb_ms.… 28.09.2025 16.02.2026
bdu:2025-12076 Уязвимость компонента kernel/trace ядра операционной системы Linux, позволяющая нарушител… 28.09.2025 16.02.2026
bdu:2025-12075 Уязвимость компонента ksmbd ядра операционной системы Linux, позволяющая нарушителю получ… 28.09.2025 16.02.2026
bdu:2025-12074 Уязвимость компонента drivers/hsi/clients/ssi_protocol.c ядра операционной системы Linux,… 28.09.2025 16.02.2026
bdu:2025-12072 Уязвимость компонента arm.c ядра операционной системы Linux, позволяющая нарушителю получ… 28.09.2025 16.02.2026
bdu:2025-12071 Уязвимость компонента kfd_process.c ядра операционной системы Linux, позволяющая нарушите… 28.09.2025 16.02.2026
bdu:2025-12069 Уязвимость компонента avic.c ядра операционной системы Linux, позволяющая нарушителю вызв… 28.09.2025 16.02.2026
bdu:2025-12068 Уязвимость компонента auth.c ядра операционной системы Linux, позволяющая нарушителю полу… 28.09.2025 16.02.2026
bdu:2025-12066 Уязвимость функции hfsc_enqueue() компонента net/sched/sch_hfsc.c ядра операционной систе… 28.09.2025 16.02.2026
bdu:2025-12065 Уязвимость компонента net/can/bcm.c ядра операционной системы Linux, позволяющая нарушите… 28.09.2025 16.02.2026
bdu:2025-12063 Уязвимость функции ksmbd_crypt_message() в модуле fs/smb/server/auth.c поддержки сервера … 28.09.2025 16.02.2026
bdu:2025-12062 Уязвимость функции chameleon_parse_gdd() ядра операционной системы Linux, позволяющая нар… 28.09.2025 16.02.2026
bdu:2025-12061 Уязвимость функции pci_register_host_bridge() ядра операционной системы Linux, позволяюща… 28.09.2025 16.02.2026
bdu:2025-12058 Уязвимость функции hash_accept() компонента crypto/algif_hash.c ядра операционной системы… 28.09.2025 16.02.2026
bdu:2025-12053 Уязвимость компонента backlight ядра операционной системы Linux, позволяющая нарушителю в… 28.09.2025 16.02.2026
bdu:2025-12052 Уязвимость ASN.1 библиотеки Libtasn1, связанная с алгоритмической сложностью, позволяющая… 28.09.2025 16.02.2026
bdu:2025-12051 Уязвимость библиотеки безопасности транспортного уровня GnuTLS, связанная с алгоритмическ… 28.09.2025 16.02.2026
ID Description Published Updated
certfr-2025-avi-0908 Multiples vulnérabilités dans Oracle PeopleSoft 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0907 Multiples vulnérabilités dans Oracle MySQL 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0906 Multiples vulnérabilités dans Oracle Java SE 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0905 Multiples vulnérabilités dans Oracle Database Server 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0904 Multiples vulnérabilités dans GitLab 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0903 Multiples vulnérabilités dans les produits Atlassian 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0902 Multiples vulnérabilités dans Xen 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0901 Vulnérabilité dans Google Chrome 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0900 Multiples vulnérabilités dans Centreon Web 2025-10-22T00:00:00.000000 2025-10-22T00:00:00.000000
certfr-2025-avi-0899 Multiples vulnérabilités dans les produits Microsoft 2025-10-20T00:00:00.000000 2025-10-20T00:00:00.000000
certfr-2025-avi-0898 Vulnérabilité dans Microsoft Edge 2025-10-20T00:00:00.000000 2025-10-20T00:00:00.000000
certfr-2025-avi-0897 Multiples vulnérabilités dans Tenable Identity Exposure 2025-10-20T00:00:00.000000 2025-10-20T00:00:00.000000
certfr-2025-avi-0896 Multiples vulnérabilités dans les produits IBM 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0895 Multiples vulnérabilités dans le noyau Linux de SUSE 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0894 Multiples vulnérabilités dans le noyau Linux de Debian LTS 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0893 Multiples vulnérabilités dans le noyau Linux de Red Hat 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0892 Multiples vulnérabilités dans le noyau Linux d'Ubuntu 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0891 Vulnérabilité dans MongoDB Connector for BI pour Windows 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0890 Multiples vulnérabilités dans les produits Moxa 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0889 Vulnérabilité dans Squid 2025-10-17T00:00:00.000000 2025-10-17T00:00:00.000000
certfr-2025-avi-0887 Vulnérabilité dans Synacor Zimbra Collaboration 2025-10-16T00:00:00.000000 2025-10-16T00:00:00.000000
certfr-2025-avi-0886 Multiples vulnérabilités dans les produits F5 2025-10-16T00:00:00.000000 2025-10-16T00:00:00.000000
certfr-2025-avi-0885 Multiples vulnérabilités dans Samba 2025-10-16T00:00:00.000000 2025-10-16T00:00:00.000000
certfr-2025-avi-0884 Multiples vulnérabilités dans les produits Cisco 2025-10-16T00:00:00.000000 2025-10-16T00:00:00.000000
certfr-2025-avi-0883 Multiples vulnérabilités dans les produits Spring 2025-10-16T00:00:00.000000 2025-10-16T00:00:00.000000
certfr-2025-avi-0801 Multiples vulnérabilités dans les produits Mattermost 2025-09-17T00:00:00.000000 2025-10-16T00:00:00.000000
certfr-2025-avi-0882 Multiples vulnérabilités dans les produits Microsoft 2025-10-15T00:00:00.000000 2025-10-15T00:00:00.000000
certfr-2025-avi-0881 Multiples vulnérabilités dans Microsoft Azure 2025-10-15T00:00:00.000000 2025-10-15T00:00:00.000000
certfr-2025-avi-0880 Multiples vulnérabilités dans Microsoft .Net 2025-10-15T00:00:00.000000 2025-10-15T00:00:00.000000
certfr-2025-avi-0879 Multiples vulnérabilités dans Microsoft Windows 2025-10-15T00:00:00.000000 2025-10-15T00:00:00.000000
ID Description Published Updated
osv-2025-54 UNKNOWN READ in Assimp::SceneCombiner::CopyScene 2025-01-22T00:15:23.827419Z 2025-03-18T00:29:47.108675Z
osv-2025-133 Stack-buffer-overflow in se_read_conf 2025-02-17T00:02:18.986364Z 2025-03-18T00:27:33.917908Z
osv-2024-1071 Use-of-uninitialized-value in Poco::Dynamic::Var::~Var 2024-09-15T00:06:58.342742Z 2025-03-18T00:25:32.915201Z
osv-2024-1322 Security exception in com.alibaba.fastjson2.JSONReader.readObject 2024-11-18T00:00:16.618504Z 2025-03-18T00:24:17.881614Z
osv-2025-148 Heap-buffer-overflow in setup_engineID 2025-02-23T00:00:36.951152Z 2025-03-18T00:22:22.817245Z
osv-2025-215 Security exception in graphql.parser.GraphqlAntlrToLanguage.createType 2025-03-18T00:09:36.655072Z 2025-03-18T00:09:36.655425Z
osv-2022-573 Heap-buffer-overflow in zim_ReflectionEnumBackedCase_getBackingValue 2022-07-13T00:00:07.763765Z 2025-03-12T17:15:50.141849Z
osv-2025-190 Heap-buffer-overflow in std::__1::__function::__func<cv::PngDecoder::compose_frame 2025-03-11T00:04:32.361664Z 2025-03-11T00:04:32.362119Z
osv-2024-831 Heap-buffer-overflow in jv_parse 2024-08-16T00:03:12.871175Z 2025-03-07T14:24:40.166702Z
osv-2024-919 Heap-buffer-overflow in validate_relpath 2024-08-16T00:09:34.461792Z 2025-03-06T14:20:56.754046Z
osv-2024-1312 Heap-buffer-overflow in jv_string_vfmt 2024-11-15T00:16:08.928897Z 2025-03-05T14:20:12.622041Z
osv-2023-1344 Heap-buffer-overflow in jv_string_vfmt 2023-12-22T00:11:40.065456Z 2025-03-05T14:16:07.938645Z
osv-2025-178 Heap-buffer-overflow in usm_set_user_password 2025-02-28T00:16:54.655227Z 2025-02-28T00:16:54.655745Z
osv-2025-177 Segv on unknown address in chunk_free_object 2025-02-28T00:16:24.018716Z 2025-02-28T00:16:24.019131Z
osv-2025-175 UNKNOWN READ in insert_free 2025-02-28T00:12:26.919208Z 2025-02-28T00:12:26.919553Z
osv-2025-174 Heap-use-after-free in gc_trace 2025-02-28T00:12:25.140274Z 2025-02-28T00:12:25.140618Z
osv-2025-173 UNKNOWN READ in chunk_obj_alloc 2025-02-28T00:11:40.566459Z 2025-02-28T00:11:40.566797Z
osv-2025-169 Stack-buffer-overflow in utf8_in2 2025-02-27T00:07:08.029075Z 2025-02-27T00:07:08.029655Z
osv-2025-165 Index-out-of-bounds in dwg_decode_eed 2025-02-26T00:17:27.930225Z 2025-02-26T00:17:27.930707Z
osv-2025-160 UNKNOWN WRITE in ndpi_free_flow_data 2025-02-24T00:07:49.495615Z 2025-02-24T00:07:49.495976Z
osv-2025-156 Check failed in CheckUnwind 2025-02-23T00:16:50.073196Z 2025-02-23T00:16:50.073520Z
osv-2025-154 UNKNOWN READ in ndpi_strdup 2025-02-23T00:13:05.487818Z 2025-02-23T00:13:05.488183Z
osv-2025-149 UNKNOWN READ in processClientServerHello 2025-02-23T00:00:50.236281Z 2025-02-23T00:00:50.236700Z
osv-2025-147 UNKNOWN WRITE in ndpi_free_flow_data 2025-02-22T00:18:07.814416Z 2025-02-22T00:18:07.814726Z
osv-2025-145 Heap-buffer-overflow in ___interceptor_strncat 2025-02-22T00:14:15.620085Z 2025-02-22T00:14:15.620535Z
osv-2023-51 Heap-use-after-free in ZSTD_freeDDict 2023-02-05T13:00:54.245269Z 2025-02-19T14:14:00.172684Z
osv-2022-1242 Heap-buffer-overflow in ZSTD_createDDict 2022-12-05T13:00:52.919257Z 2025-02-19T14:09:48.094157Z
osv-2023-1329 Stack-buffer-overflow in decNaNs 2023-12-18T00:13:42.545765Z 2025-02-17T14:14:20.492923Z
osv-2025-127 Object-size in unpack_dsd_samples 2025-02-15T00:16:56.314634Z 2025-02-15T00:16:56.315060Z
osv-2025-124 Use-of-uninitialized-value in get_word 2025-02-15T00:09:23.967012Z 2025-02-15T00:09:23.967345Z
ID Description Published Updated
rustsec-2022-0054 wee_alloc is Unmaintained 2022-05-11T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0052 `os_socketaddr` invalidly assumes the memory layout of std::net::SocketAddr 2022-08-26T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0051 Memory corruption in liblz4 2022-08-25T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0049 Use after free in MacOS / iOS implementation 2022-08-15T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0047 Post-Quantum Signature scheme Rainbow level I parametersets broken 2022-02-25T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0046 Out-of-bounds read when opening multiple column families with TTL 2022-05-11T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0045 Post-Quantum Key Encapsulation Mechanism SIKE broken 2022-07-30T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0043 Improper validation of Windows paths could lead to directory traversal attack 2022-01-21T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0035 Unbounded memory allocation based on untrusted length 2022-08-01T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0033 Heap memory corruption with RSA private key operation 2022-07-05T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0032 AES OCB fails to encrypt some bytes 2022-07-05T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0029 `MsQueue` `push`/`pop` use the wrong orderings 2022-06-07T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0028 Use after free in Neon external buffers 2022-05-22T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0027 `OCSP_basic_verify` may incorrectly verify the response signing certificate 2022-05-03T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0026 Incorrect MAC key used in the RC4-MD5 ciphersuite 2022-05-03T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0025 Resource leakage when decoding certificates and keys 2022-05-03T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0022 Parser creates invalid uninitialized value 2022-05-10T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0021 `SegQueue` creates zero value of any type 2022-05-10T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0020 `SegQueue` creates zero value of any type 2022-05-10T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0019 Channel creates zero value of any type 2022-05-10T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0018 Timing attack 2022-05-09T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0017 `array!` macro is unsound when its length is impure constant 2022-04-27T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0016 Use after free with `externref`s and epoch interruption in Wasmtime 2022-03-31T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0014 Infinite loop in `BN_mod_sqrt()` reachable when parsing certificates 2022-03-15T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0013 Regexes with large repetitions on empty sub-expressions take a very long time to parse 2022-03-08T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0012 Arrow2 allows double free in `safe` code 2022-03-04T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0011 Miscomputation when performing AES encryption in rust-crypto 2022-02-28T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0010 enum_map macro can cause UB when `Enum` trait is incorrectly implemented 2022-02-17T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0009 Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord` 2022-02-07T12:00:00Z 2023-06-13T13:10:24Z
rustsec-2022-0008 Delegate functions are missing `Send` bound 2022-01-02T12:00:00Z 2023-06-13T13:10:24Z
ID Description Published Updated
alsa-2025:15021 Important: postgresql:13 security update 2025-09-02T00:00:00Z 2025-09-29T09:05:39Z
alsa-2025:15023 Moderate: httpd security update 2025-09-02T00:00:00Z 2025-09-29T09:03:21Z
alsa-2025:15701 Important: cups security update 2025-09-11T00:00:00Z 2025-09-29T09:01:08Z
alsa-2025:15700 Important: cups security update 2025-09-11T00:00:00Z 2025-09-29T08:59:02Z
alsa-2025:15687 Moderate: php:8.2 security update 2025-09-11T00:00:00Z 2025-09-29T08:55:43Z
alsa-2025:16108 Important: firefox security update 2025-09-17T00:00:00Z 2025-09-29T08:52:33Z
alsa-2025:16086 Moderate: mysql security update 2025-09-17T00:00:00Z 2025-09-29T08:50:56Z
alsa-2025:15900 Important: podman security update 2025-09-16T00:00:00Z 2025-09-29T08:49:02Z
alsa-2025:16116 Moderate: gnutls security, bug fix, and enhancement update 2025-09-17T00:00:00Z 2025-09-29T08:47:08Z
alsa-2025:16398 Moderate: kernel security update 2025-09-22T00:00:00Z 2025-09-29T08:44:37Z
alsa-2025:16428 Moderate: libtpms security update 2025-09-23T00:00:00Z 2025-09-29T08:40:24Z
alsa-2025:16441 Moderate: avahi security update 2025-09-23T00:00:00Z 2025-09-29T08:38:23Z
alsa-2025:16156 Important: thunderbird security update 2025-09-18T00:00:00Z 2025-09-26T11:14:21Z
alsa-2025:15782 Moderate: kernel security update 2025-09-15T00:00:00Z 2025-09-26T10:01:17Z
alsa-2025:16157 Important: thunderbird security update 2025-09-18T00:00:00Z 2025-09-26T09:47:50Z
alsa-2025:16589 Important: thunderbird security update 2025-09-24T00:00:00Z 2025-09-25T15:05:39Z
alsa-2025:16109 Important: firefox security update 2025-09-17T00:00:00Z 2025-09-25T15:04:05Z
alsa-2025:16260 Important: firefox security update 2025-09-22T00:00:00Z 2025-09-25T15:01:51Z
alsa-2025:16154 Moderate: grub2 security update 2025-09-18T00:00:00Z 2025-09-25T11:34:59Z
alsa-2025:15740 Moderate: kernel security update 2025-09-15T00:00:00Z 2025-09-25T08:48:24Z
alsa-2025:16372 Moderate: kernel security update 2025-09-22T00:00:00Z 2025-09-24T11:04:13Z
alsa-2025:16373 Moderate: kernel-rt security update 2025-09-22T00:00:00Z 2025-09-24T11:00:38Z
alsa-2025:15785 Important: kernel security update 2025-09-15T00:00:00Z 2025-09-23T12:06:04Z
alsa-2025:15874 Moderate: python-cryptography security update 2025-09-16T00:00:00Z 2025-09-18T10:25:39Z
alsa-2025:15887 Moderate: opentelemetry-collector security update 2025-09-16T00:00:00Z 2025-09-18T08:42:35Z
alsa-2025:16046 Moderate: mysql:8.4 security update 2025-09-17T00:00:00Z 2025-09-18T08:40:08Z
alsa-2025:16115 Moderate: gnutls security, bug fix, and enhancement update 2025-09-17T00:00:00Z 2025-09-18T08:34:55Z
alsa-2025:15662 Important: kernel security update 2025-09-11T00:00:00Z 2025-09-17T11:09:33Z
alsa-2025:15904 Important: container-tools:rhel8 security update 2025-09-16T00:00:00Z 2025-09-17T08:50:36Z
alsa-2025:15661 Important: kernel security update 2025-09-11T00:00:00Z 2025-09-16T09:35:20Z